How to black out text in a PDF so it actually stays hidden

Drawing a black box over a PDF hides nothing: the text is still underneath and can be copied out. Here is why that happens, three methods that really remove information, and a one-minute test to check your work.

Sooner or later most people need to send a document with something taken out of it: an account number on a bank statement, a salary on a payslip, a child's name on a form, a client's details in a report. The obvious move is to draw a black rectangle over the sensitive part and save the file. On screen it looks finished. In most cases, nothing has been hidden at all.

This is not a rare mistake made by careless people. In January 2019, lawyers for Paul Manafort filed a court document in the United States whose blacked-out passages could be read by anyone who selected the text and pasted it into another program. Government agencies, law firms and large companies have made the same error, repeatedly, because the tools make it so easy to make.

Why the black box fails

A PDF page is not a flat picture. It is a stack of separate objects: lines of text, images, shapes and annotations, each drawn on top of the one before. When you draw a black rectangle in a PDF editor, or use a highlighter set to black, you add one more object to the top of that stack. The text you wanted to hide is still in the file, exactly where it was. It is simply painted over.

Anything that reads the file rather than looking at it will find that text immediately:

  • Copy and paste. Select the area, copy, paste into a text editor. The hidden words appear.
  • Search. Press Ctrl+F and search for the account number. The reader jumps straight to it.
  • Text extraction. Any PDF-to-text tool, including the one on this site, reads the text layer and ignores the box entirely.
  • Screen readers and search engines. Both work from the text layer, not from what the page looks like.
  • Editing. Anyone with a PDF editor can click the rectangle and delete it.

Two other popular tricks fail for the same reason. Changing the text colour to white leaves the words in place in a colour you cannot see. Covering them with a shape in Word before exporting does the same thing one step earlier.

What real redaction does

Proper redaction is a destructive edit. It deletes the characters from the page's content, removes or cuts any image that sits under the area, and only then draws a box to show that something was removed. After that, the information is not in the file at all, so nothing can find it.

A careful redaction also deals with places where the same information might be stored without being visible on the page: the document's metadata, comments and annotations, form fields, bookmarks, attached files, and earlier versions of the file kept by an editor that saves changes by adding to the end of the file rather than rewriting it.

There are three reliable ways to get there. Which one suits you depends on what you are removing and what software you have.

Method one: remove the whole page

The simplest redaction is the one people forget. If the sensitive information sits on a page the recipient does not need, do not black it out. Delete the page.

A landlord asking for proof of income needs the summary page of a payslip, not the page listing your pension and loan deductions. A visa officer asking for a bank statement usually needs the pages showing the balance, not every transaction from the last quarter. Sending fewer pages is cleaner, smaller and leaves nothing to recover. Use Remove pages to drop what is not needed, or Extract pages to build a new file from only the pages you choose.

This only works when whole pages can go. If the sensitive line sits in the middle of a page the recipient must see, you need one of the next two methods.

Method two: use a real redaction tool

Some software has a genuine redaction feature that deletes the content underneath the box.

  • Adobe Acrobat Pro has a Redact tool. You mark the areas first, then apply the redactions as a separate step, and the program can also remove hidden information such as metadata and comments. The free Adobe Reader does not include it.
  • LibreOffice, which is free, has had a Redact feature since version 6.4. Open the PDF in LibreOffice Draw, choose Tools > Redact, draw your boxes, and use the redacted export. It produces a PDF in which the pages have been turned into images, so the covered text no longer exists.

Whatever tool you use, read its steps carefully. In tools that separate marking from applying, a document with marks that have not yet been applied looks redacted on screen but is not.

Method three: flatten the page to an image

If you do not have a redaction tool, you can get the same result by turning the page into a picture, covering the area in that picture, and turning it back into a PDF. Once a page is a picture, there is no text layer left to copy, search or extract.

  1. Convert the page to an image with PDF to JPG. Choose 200 or 300 DPI so small print stays legible.
  2. Open the image in any image editor, such as Paint on Windows or Preview on a Mac, and draw a solid, fully opaque black rectangle over the area.
  3. Save the image, then rebuild the PDF with JPG to PDF. If only some pages needed redacting, merge the rebuilt pages back with the untouched ones in Merge PDF.

Two cautions. First, use a solid shape tool, not a highlighter or a marker pen. The highlighter in most phone and photo markup tools is semi-transparent, and a few adjustments to brightness and contrast can bring the text back. Second, do not blur or pixelate text. Blurring looks convincing, but blurred and pixelated text has been reconstructed more than once, particularly short strings such as numbers. A solid block leaves nothing to work with.

The trade-off is that a flattened page is a picture: its text can no longer be selected or searched, and the file will usually be larger. For a two-page statement that does not matter. For a long report, a real redaction tool is the better choice.

Check your work in one minute

Never assume a redaction worked. Test the file you are about to send, not the one you edited earlier.

  1. Select all and paste. Open the final PDF, press Ctrl+A and Ctrl+C, and paste into a plain text editor. Read through it. If the hidden text appears, the redaction failed.
  2. Search for it. Use the reader's search box to look for the exact number or name you removed. It should not be found.
  3. Extract the text. Run the file through PDF to text as a second opinion. It reads the text layer directly.
  4. Check the properties. Look at the title, author and subject fields with PDF metadata. A title such as Payslip - full salary breakdown undoes a lot of careful work.

Other places information leaks

Even a perfect redaction can be undermined by what is around it.

The file name. A file called ramesh-account-01234567-statement.pdf reveals what you redacted inside it. Rename it before sending.

The size of the box. A box that fits a name exactly tells the reader how long the name is. Combined with context, that can be enough to guess it. Where it matters, make boxes a little larger than the text they cover.

Repeated information. An account number blacked out in the header may appear again in a footer, a reference code or a barcode on the same page. Look for every occurrence, not just the obvious one.

Earlier copies. If you already emailed the unredacted version to the wrong address, or saved it in a shared folder, redacting the file now does not reach those copies.


Remove pages, PDF to JPG and JPG to PDF all run in your browser, so the unredacted original never leaves your computer while you work on it.


Tools mentioned in this guide

Free, unlimited, and they run in your browser rather than on a server.

Written by Santosh Khatiwada, an independent developer who builds these tools. Spotted an error, or want something covered? Get in touch.